arrow
返回

An effective and practical gradient inversion attack

delete2022-08-19
delete4
delete
OA
AI
Z
Zeren Luo
C
Chuangwei Zhu
L
Lujie Fang
G
Guang Kou
R
Ruitao Hou
X
Xianmin Wang *
DOI:10.1002/int.22997delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
While gradient aggregation playing a vital role in federated or collaborative learning, recent studies have revealed that gradient aggregation may suffer from some attacks, such as gradient inversion, where the private training data can be recovered from the shared gradients. However, the performance of the existing attack methods is limited because they usually require prior knowledge in Batch Normalization and could only reconstruct a single image or a small batch one. To make the attacks less restrictive and more applicable, we propose an effective and practical gradient inversion method in this paper. Specifically, we use cosine similarity to measure the difference of gradients between the synthesized and ground-truth images, and then construct an input regularization for the fully connected layer to ensure the fidelity of the image. Moreover, we apply the total variation denoising strategy to the convolution feature map for further improving the smoothness of the reconstructed image. Experimental results demonstrate that our method can reconstruct high fidelity training data on a large batch size for complex data sets, such as ImageNet.
Keyword:
federated learning
gradient sharing
machine learning
privacy protection

期刊

International Journal of Intelligent Systems 封面图
International Journal of Intelligent Systems
IF:
3.7
论文数:
3.1K
被引数:
8.1K

机构

G
Guangzhou University
学者数:
1.8W
论文数: 1.3W
被引数: 1.8W
引用论文

引用论文

Parkinson's disease: Nigral receptor changes support peptidergic role in nigrostriatal modulation
err2004-10-08
err0
PREAI
errGeorge R. Uhl; Gail O. Hackney; Mary Torchia; Victoria Stranov; Wallace W. Tourtellotte; Peter J. Whitehouse; Vinh Tran; Steven Strittmatter
err分享
err收藏
ELAA: An efficient local adversarial attack using model interpreters
err2021-09-19
err5
errOAAI
errGuo, Shangwei; Geng, Siyuan; Xiang, Tao; Liu, Hangcheng; Hou, Ruitao
err分享
err收藏
err分享
err收藏
Adversarial attacks on deep-learning-based SAR image target recognition
err2020-07-01
err86
PREAI
errHuang, Teng; Zhang, Qixiang; Liu, Jiabao; Hou, Ruitao; Wang, Xianmin; Li, Ya
err分享
err收藏
学者 查看更多内容